Penetration Tester
Job Summary
We are an IT Solutions Integrator/Consulting Firm helping our clients hire the right professional for an exciting long-term project. Here are a few details.
Experience:3-8 Years
We are looking for an experienced Application Security / Web Penetration Testing professional with strong hands-on expertise in manual and automated security testing of web applications. The ideal candidate should have a solid understanding of the OWASP Top 10 vulnerability assessment methodologies risk prioritization and secure remediation practices.
The candidate will be responsible for identifying and validating application security vulnerabilities assessing their business impact preparing detailed security reports and working closely with development and business stakeholders throughout the vulnerability remediation lifecycle.
- Conduct manual and automated security testing of web applications to identify security vulnerabilities and weaknesses.
- Perform application security assessments covering authentication authorization session management input validation business logic API security and other application components.
- Demonstrate strong knowledge and practical application of the OWASP Top 10 framework.
- Identify validate and exploit vulnerabilities using appropriate penetration testing methodologies and tools.
- Analyze vulnerabilities and prioritize findings based on:
- Severity
- Exploitability
- Business impact
- Compliance implications
- Exposure and attack likelihood
- Severity
- Perform vulnerability validation and develop Proof of Concept (PoC) demonstrating the impact and exploitability of identified vulnerabilities.
- Prepare comprehensive security assessment and penetration testing reports containing:
- Vulnerability description
- Affected application/component
- Technical details
- Evidence/screenshots
- Proof of Concept
- Risk rating/severity
- Business impact
- Remediation recommendations
- Vulnerability description
- Collaborate with developers application owners architects and other stakeholders to explain security findings.
- Provide practical security guidance and remediation recommendations throughout the vulnerability remediation lifecycle.
- Track identified vulnerabilities and support development teams in understanding and resolving security issues.
- Perform retesting/reassessment of remediated vulnerabilities to confirm that fixes are effective.
- Verify that remediation activities have not introduced new security vulnerabilities or regression issues.
- Present security findings risk implications and remediation priorities to technical teams and executive stakeholders.
- Stay current with emerging web application vulnerabilities attack techniques security standards and application security best practices.
- Strong hands-on experience in Web Application Security Testing / Penetration Testing.
- Strong understanding of OWASP Top 10 and common web application vulnerabilities.
- Experience with vulnerabilities such as:
- SQL Injection
- Cross-Site Scripting (XSS)
- CSRF
- Broken Access Control
- IDOR/BOLA
- Authentication & Session Management issues
- Security Misconfiguration
- SSRF
- File Upload vulnerabilities
- Command Injection
- XXE
- Path Traversal
- Business Logic vulnerabilities
- API security vulnerabilities
- SQL Injection
- Experience performing both manual and automated vulnerability assessments.
- Ability to understand application architecture request/response flows authentication mechanisms and APIs.
- Strong ability to validate vulnerabilities and distinguish true positives from false positives.
- Experience creating detailed PoCs and technical security reports.
- Good understanding of vulnerability severity and risk-rating methodologies such as CVSS.
- Knowledge of secure coding and application security remediation practices.
Required Skills:
Description Conduct manual and automated testing of web application Should have good understanding about OWASP Top 10 framework Prioritize vulnerabilities based on severity exploitability compliance implications and potential business impact. Produce detailed security assessment reports that include vulnerability descriptions proof of concept risk ratings and remediation recommendations Work with stakeholders to explain findings support remediation efforts and provide security guidance throughout the remediation lifecycle. Reassess remediated vulnerabilities to confirm fixes are effective and that no new security issues have been introduced. Present findings and risk implications to technical and executive stakeholders.
Required Education:
BE / / MCA / . in Computer Science or equivalent degree from an accredited university.